VendorsIBMwebsphere_application_serverany version
Vulnerabilities

IBM WebSphere Application Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

237CVEs
CVE-2015-5041
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
Published 2016-06-06 · Modified
9.1EPSS 0.039
CVE-2023-27554
IBM WebSphere Application Server XML external entity injection
Published 2023-05-11 · Modified
9.1EPSS 0.009
CVE-2026-8646
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-06-22 · Analyzed
9.1EPSS 0.006
CVE-2026-8644
IBM WebSphere Application Server is affected by an identity spoofing vulnerability
Published 2026-06-01 · Analyzed
9.1EPSS 0.005
CVE-2026-9006
IBM WebSphere Application Server is affected by server-side request forgery
Published 2026-06-22 · Analyzed
9.1EPSS 0.004
CVE-2020-4464
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.
Published 2020-07-17 · Modified
9.0EPSS 0.132
CVE-2026-9311
IBM WebSphere Application Server is affected by remote code execution
Published 2026-06-01 · Analyzed
9.0EPSS 0.006
CVE-2026-9319
IBM WebSphere Application Server is affected by a remote code execution vulnerability
Published 2026-06-01 · Analyzed
9.0EPSS 0.006
CVE-2017-1731
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.
Published 2018-01-30 · Modified
8.8EPSS 0.028
CVE-2020-4362
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. IBM X-Force ID: 178929.
Published 2020-04-10 · Modified
8.8EPSS 0.024
CVE-2021-39031
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.
Published 2022-01-25 · Modified
8.8EPSS 0.020
CVE-2018-1901
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.
Published 2018-12-12 · Modified
8.8EPSS 0.015
CVE-2018-1926
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious URL, a remote attacker could send a specially-crafted request. An attacker could exploit this vulnerability to perform CSRF attack and update available applications. IBM X-Force ID: 152992.
Published 2018-12-12 · Modified
8.8EPSS 0.012
CVE-2021-29736
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.
Published 2021-07-30 · Modified
8.8EPSS 0.011
CVE-2022-22476
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
Published 2022-07-08 · Modified
8.8EPSS 0.009
CVE-2021-29754
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Published 2021-06-11 · Modified
8.8EPSS 0.007
CVE-2026-14980
IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
Published 2026-07-30 · Analyzed
8.8EPSS 0.004
CVE-2026-2482
IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
Published 2026-07-29 · Analyzed
8.8EPSS 0.002
CVE-2026-15064
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-07-28 · Modified
8.7EPSS 0.003
CVE-2026-15325
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
Published 2026-07-28 · Modified
8.7EPSS 0.003
CVE-2026-9330
IBM WebSphere Application Server is affected by remote code execution
Published 2026-06-01 · Analyzed
8.5EPSS 0.007
CVE-2026-11536
IBM WebSphere Application Server is affected by a remote code execution vulnerability
Published 2026-07-30 · Analyzed
8.5EPSS 0.006
CVE-2026-11594
IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities
Published 2026-06-30 · Analyzed
8.5EPSS 0.003
CVE-2021-20353
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.
Published 2021-02-10 · Modified
8.2EPSS 0.052
CVE-2020-4949
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
Published 2021-01-26 · Modified
8.2EPSS 0.048
CVE-2021-20454
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.
Published 2021-04-21 · Modified
8.2EPSS 0.028
CVE-2021-20453
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196648.
Published 2021-04-20 · Modified
8.2EPSS 0.025
CVE-2021-20492
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
Published 2021-05-26 · Modified
8.2EPSS 0.021
CVE-2018-1840
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
Published 2018-12-03 · Modified
8.1EPSS 0.021
CVE-2026-18499
IBM WebSphere Application Server Liberty is affected by a privilege escalation
Published 2026-08-12 · Analyzed
8.1EPSS 0.004
CVE-2026-15328
IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP Requests
Published 2026-07-28 · Modified
8.1EPSS 0.004
CVE-2026-9327
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published 2026-09-10 · Analyzed
8.1EPSS 0.004
CVE-2021-20354
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.
Published 2021-02-18 · Modified
7.8EPSS 0.041
CVE-2007-3262
Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.
Published 2007-06-19 · Modified
7.8EPSS 0.029
CVE-2013-3024
IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362.
Published 2018-05-24 · Modified
7.8EPSS 0.004
CVE-2025-14914
IBM WebSphere Application Server Liberty Path Traversal
Published 2026-02-02 · Analyzed
7.6EPSS 0.004
CVE-2025-33104
IBM WebSphere Application Server cross
Published 2025-05-14 · Analyzed
7.6EPSS 0.002
CVE-2020-4449
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230.
Published 2020-06-05 · Modified
7.5EPSS 0.039
CVE-2019-4046
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory. IBM X-Force ID: 156242.
Published 2019-03-25 · Modified
7.5EPSS 0.032
CVE-2020-4276
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
Published 2020-03-26 · Modified
7.5EPSS 0.031
← Prev2 / 6Next →